Description
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which requires a system restart to recover service.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://www.twcert.org.tw/tw/cp-132-6227-eaf49-1.html
Scores
CVSS v3
7.5
EPSS
0.0128
EPSS Percentile
66.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-1284
CWE-122
Status
published
Products (1)
nhi/health_insurance_web_service_component
Published
Jun 20, 2022
Tracked Since
Feb 18, 2026